Case study

Trapping a Mustang Panda

IBM X-Force and Deception.Pro recorded two incidents in simulated organizations, observing reconnaissance, malware deployment and fake-document exfiltration.

DecoyAdversary engagementEndpointOT/ICS

Vendor-published case study

Critical reading · Sep 15, 2026

What the source supports

IBM X-Force describes two incidents in simulated organizations with fake documents.

Question for evaluation

Which parts of the simulation shaped the observed behavior?

This note is bounded by the material shown under “Review depth”. It is not an independent test.

Evidence limits

Two incidents illustrate behavior; they do not establish a general success rate.

Sources and provenance

  1. Trapping a Mustang Panda
    source-page · 2026-09-15

Reviewed: 2026-09-15. This record may change when new evidence is found.

RIS · BibTeX

Related resources

Product

Deception.Pro

Review: Public pageCritical reading

Persistent instrumented environments for malware detonation and adversary observation, according to the platform description.

NetworkEndpointDecoyAdversary engagement